ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwarenjRAT

njRAT is capable of logging keystrokes.

T1056.001
Keylogging
MalwareJPIN

JPIN contains a custom keylogger.

T1056.001
Keylogging
MalwaremetaMain

metaMain has the ability to log keyboard events.

T1056.001
Keylogging
MalwareHTTPBrowser

HTTPBrowser is capable of capturing keystrokes on victims.

T1056.001
Keylogging
MalwareAgent Tesla

Agent Tesla can log keystrokes on the victim’s machine.

T1056.001
Keylogging
MalwareECCENTRICBANDWAGON

ECCENTRICBANDWAGON can capture and store keystrokes.

T1056.001
Keylogging
MalwareBADNEWS

When it first starts, BADNEWS spawns a new thread to log keystrokes.

T1056.001
Keylogging
MalwareDRYHOOK

DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device.

T1056.001
Keylogging
MalwareRemexi

Remexi gathers and exfiltrates keystrokes from the machine.

T1056.001
Keylogging
MalwareAstaroth

Astaroth logs keystrokes from the victim's machine.

T1056.001
Keylogging
MalwareQakBot

QakBot can capture keystrokes on a compromised host.

T1056.001
Keylogging
MalwarejRAT

jRAT has the capability to log keystrokes from the victim’s machine, both offline and online.

T1056.001
Keylogging
MalwareHelminth

The executable version of Helminth has a module to log keystrokes.

T1056.001
Keylogging
MalwareMacSpy

MacSpy captures keystrokes.

T1056.001
Keylogging
MalwareDtrack

Dtrack’s dropper contains a keylogging executable.

T1056.001
Keylogging
MalwareADVSTORESHELL

ADVSTORESHELL can perform keylogging.

T1056.001
Keylogging
MalwareWarzoneRAT

WarzoneRAT has the capability to install a live and offline keylogger, including through the use of the `GetAsyncKeyState` Windows API.

T1056.001
Keylogging
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has a keylogging capability.

T1056.001
Keylogging
ToolSILENTTRINITY

SILENTTRINITY has a keylogging capability.

T1056.001
Keylogging
ToolPowerSploit

PowerSploit's Get-Keystrokes Exfiltration module can log keystrokes.

T1056.001
Keylogging
ToolDCRAT

DCRAT can log keystrokes on targeted systems.

T1056.001
Keylogging
ToolEmpire

Empire includes keylogging capabilities for Windows, Linux, and macOS systems.

T1056.001
Keylogging
ToolPcShare

PcShare has the ability to capture keystrokes.

T1056.001
Keylogging
ToolPoshC2

PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages.

T1056.001
Keylogging
ToolAsyncRAT

AsyncRAT can capture keystrokes on the victim’s machine.

T1056.001
Keylogging
ToolRemcos

Remcos has a command for keylogging.

T1056.001
Keylogging
ToolImminent Monitor

Imminent Monitor has a keylogging module.

T1056.001
Keylogging
ToolPupy

Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped.

T1056.001
Keylogging
ToolQuasarRAT

QuasarRAT has a built-in keylogger.

T1056.001
Keylogging
MalwareDuqu

Duqu can track key presses with a keylogger module.

T1056.002
GUI Input Capture
MalwareiKitten

iKitten prompts the user for their credentials.

T1056.002
GUI Input Capture
MalwareCuckoo Stealer

Cuckoo Stealer has captured passwords by prompting victims with a “macOS needs to access System Settings” GUI window.

T1056.002
GUI Input Capture
MalwareKeydnap

Keydnap prompts the users for credentials.

T1056.002
GUI Input Capture
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1056.002
GUI Input Capture
MalwareMuddyViper

MuddyViper has displayed a fake Windows Security dialog to gather credentials.

T1056.002
GUI Input Capture
MalwareBundlore

Bundlore prompts the user for their credentials.

T1056.002
GUI Input Capture
MalwareLP-Notes

LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials.

T1056.002
GUI Input Capture
MalwareMetamorfo

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.

T1056.002
GUI Input Capture
MalwareCalisto

Calisto presents an input prompt asking for the user's login and password.

T1056.002
GUI Input Capture
MalwareProton

Proton prompts users for their credentials.

T1056.002
GUI Input Capture
MalwareXCSSET

XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.

T1056.002
GUI Input Capture
MalwareDok

Dok prompts the user for credentials.

T1056.002
GUI Input Capture
ToolSILENTTRINITY

SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials.

T1056.003
Web Portal Capture
MalwareWARPWIRE

WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP.

T1056.003
Web Portal Capture
MalwareIceApple

The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials.

T1056.004
Credential API Hooking
MalwareTrickBot

TrickBot has the ability to capture RDP credentials by capturing the CredEnumerateA API

T1056.004
Credential API Hooking
MalwareRDFSNIFFER

RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface.

T1056.004
Credential API Hooking
MalwareNOKKI

NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine.

T1056.004
Credential API Hooking
MalwareVersaMem

VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server.

T1056.004
Credential API Hooking
MalwareUrsnif

Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.